How to handle sign-up with new mobile numbers incase it is already registered by its previous user?

Viewed 23

In India, Mobile numbers that are unused for a while are disabled and are usually recycled and given to new customers.

Assuming that the app/website has mobile number based authentication, how can we handle scenarios in case the previous user of that mobile number had also created an account with same number?

On top of my head, I can think of issues like,

  • Incase of OTP Login, security and data protection of previous user.
  • Incase of password based login, new user won't be able to sign up on mobile number based login system with mobile as primary and unique key.
1 Answers

As you that the mobile number can change its owner, I would never rely on the mobile as the sole factor of authentication. So, avoid solutions like:

  • an OTP sent to the mobile is the only factor of authentication
  • the mobile number is used as the user's login together with a password, but resetting the password only requires confirming the reset with an OTP sent to mobile

In authentication, we talk about three groups of authenticators:

  • authenticate with something the user knows (e.g. a password)
  • authenticate with something the user has (e.g. a security key, a mobile phone to provide an OTP, an authenticator app)
  • authenticate with something the user is (biometrics)

In your case, you would have to make sure that you add a second factor of authentication that is either something the user knows or something the user is. This will help you make sure that the same mobile number is not used to log in to someone else's account.

You could also require logging in with an authenticator app if you know that it will not limit your users. This will essentially tie the account to a concrete device, not just a number.

Related